HoneyLabs

UDP traffic

Datagrams matching asn:3215 sent to HoneyLabs sensors over UDP in the last 7 days. DNS questions and QUIC client fingerprints are decoded on the sensor. Other datagrams are kept as their first bytes and labelled by protocol where it can be recognised.

A UDP source address can be forged, so each address listed here either sent the traffic or was impersonated by whoever did. UDP traffic is kept out of verdicts, feeds, watchlists and alerts.

47

Datagrams

26

Source addresses

1

Networks

3

Countries

45

Destination ports

Traffic by type

Other services

23 datagrams from 15 sources

First packets of sessions with VPN, voice, tunnelling, database and management services.

Latest SOCKS5 datagram, to 22003/udp

·4Vx·

payload bytes
00000000  05 00 ff ff 00 fe fe fe  fe fd fd fd fd 12 34 56  |..............4V|
00000010  78 06 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |x...............|
00000020  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
00000030  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
00000040  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
00000050  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
00000060  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
00000070  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
00000080  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
00000090  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
000000a0  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
000000b0  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
000000c0  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
000000d0  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
000000e0  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
000000f0  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|

Unrecognised

24 datagrams from 15 sources

Datagrams no decoder recognised. Their first bytes are kept.

Latest Unrecognised datagram, to 37971/udp

·(·V·r ·4Vx·O·1·H

payload bytes
00000000  01 a0 14 28 d1 56 91 72  0d 00 ff ff 00 fe fe fe  |...(.V.r........|
00000010  fe fd fd fd fd 12 34 56  78 db 0f 4f a8 8f 31 15  |......4Vx..O..1.|
00000020  48                                                |H|

Amplification checks

Probes for services that answer a small request with a much larger reply, the property reflection attacks rely on.

ServicePortDatagramsSourcesFactor
Memcached11211/udp1110,000 to 51,000

The factor is how many bytes a reachable server can send back for each byte it receives, as published by CISA in alert TA14-017A.

Destination ports

Networks

Countries

Source addresses (unverified)

AddressNetworkCcSendsDatagramsLast seen (UTC)
86.252.45.174AS3215 OrangeFRSOCKS542026-10-09 01:31
90.73.208.73AS3215 OrangeFRUnrecognised42026-10-10 22:46
109.221.246.15AS3215 OrangeFRSOCKS532026-10-07 12:07
2.12.43.124AS3215 OrangeFRSOCKS532026-10-07 22:04
82.127.126.14AS3215 OrangeFRSOCKS532026-10-09 20:38
82.120.147.243AS3215 OrangeFRUnrecognised32026-10-07 14:20
83.200.225.79AS3215 OrangeFRUnrecognised32026-10-10 00:44
90.52.184.55AS3215 OrangeFRUnrecognised22026-10-05 19:01
90.76.85.88AS3215 OrangeFRUnrecognised22026-10-09 13:02
92.142.110.25AS3215 OrangeGFSOCKS522026-10-07 01:37
90.51.142.7AS3215 OrangeFRUnrecognised22026-10-07 04:21
83.204.12.141AS3215 OrangeFRUnrecognised22026-10-05 18:15
82.121.167.49AS3215 OrangeFRUnrecognised12026-10-06 06:22
90.62.241.177AS3215 OrangeFRSOCKS512026-10-06 11:23
82.127.132.221AS3215 OrangeFRUnrecognised12026-10-08 19:44
92.170.191.59AS3215 OrangeFRUnrecognised12026-10-07 00:18
92.148.162.128AS3215 OrangeFRSOCKS512026-10-08 10:55
82.121.168.35AS3215 OrangeFRSOCKS512026-10-09 14:02
2.11.114.114AS3215 OrangeFRUnrecognised12026-10-05 13:46
86.220.129.59AS3215 OrangeFRSOCKS512026-10-09 09:20

Latest datagrams